[ LEGAL ]Security

Security

Updated 22 Aug 2026 · Vaidra

How Vaidra protects the Platform today. This is a product description, not a certification, not a HIPAA business associate agreement, and not a guarantee that systems cannot fail or be abused.

01

What we do not claim

We do not claim HIPAA compliance, SOC 2, ISO 27001, or CDSCO medical-device registration. If your hospital needs a signed processing addendum or a specific control set, ask us before a production rollout — do not assume this page is that contract.

02

Controls in production

  • Transport: HTTPS/TLS between browsers, the API, and our cloud load balancer.
  • Database: clinical records in PostgreSQL on AWS RDS with encryption at rest enabled; the database is not publicly reachable.
  • Isolation: clinical records are scoped to the practitioner or organisation tenant; other tenants cannot read that chart.
  • Sign-in: Google OAuth for clinicians; a first-party session cookie on the Platform.
  • Object storage: consult recordings and encounter attachments (images, PDFs, sketches) stored in Cloudflare R2 (provider-side encryption at rest).
  • Human review: the product is built so clinicians accept, edit, or reject drafts before they commit to the chart.

Application-level encryption of every AI payload is not claimed. Speech and language vendors receive audio or text in order to transcribe and draft. LLM traces may be encrypted at rest when the trace key is configured. Operational logs and optional browser error reports go to our observability provider.

03

What practices must do

  • Tell patients when a consult is recorded.
  • Use workstations and Google accounts you control; invite only authorised staff.
  • Review every note, prescription, and summary before it leaves the room.
  • Agree retention and hospital security requirements with us in writing when they go beyond this page. We do not currently offer self-serve workspace export.
04

Incidents and contact

If you believe there is a security issue in Vaidra, email hello@vaidra.care with enough detail to reproduce it. Do not include unnecessary patient identifiers in the first message.

Privacy details: Privacy Policy. Vendors: Subprocessors.